Project

General

Profile

Actions

Feature #2270

closed

Suricata-update: support profiles

Added by Anthony Verez over 6 years ago. Updated almost 5 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
-
Effort:
Difficulty:
Label:

Description

Our sensors are running in different environments.
We would like to be able to create profiles, the profile to use should be passed on the command line.
Each profile could use different configuration rules to enable/disable/modify different sets of rules.

Actions #1

Updated by Victor Julien over 6 years ago

  • Project changed from Suricata to Suricata-Update
Actions #2

Updated by Victor Julien about 5 years ago

If all of the options could be controlled by the yaml, simply specifying a different yaml would count as a profile I guess? Not sure if there are things currently that can't be controlled through the yaml.

Actions #3

Updated by Jason Ish about 5 years ago

Victor Julien wrote:

If all of the options could be controlled by the yaml, simply specifying a different yaml would count as a profile I guess? Not sure if there are things currently that can't be controlled through the yaml.

I don't think there is anything that can't be controlled by the configuration file. There may have been, pre-1.0 when this bug was created, but yes, using a configuration file should be able to override everything.

I guess one issue when "profiles" are discussed is that it might be hard to share a "base" configuration. But I'm not sure if this is in scope of Suricata-Update, probably better for the orchestration tools built around it. The most I'd consider if a way to include files into others, for example, disable.conf could include another disable.conf, which could serve as the base configuration. This could give you some level of inheritance between configurations, and is rather simple to develop and maintain on our end.

Actions #4

Updated by Shivani Bhardwaj almost 5 years ago

  • Status changed from New to Closed
Actions

Also available in: Atom PDF